Software-Defined Warfare: Expanding the Frontier

Software-Defined Warfare: Expanding the Frontier

Software Engineering Institute (SEI) Podcast Series

B2July 8, 202612 min
Play

Software-defined warfare is today's reality for national security, shifting the emphasis in military operations from hardware to software. In the latest podcast from the Carnegie Mellon University Software Engineering Institute, SEI director Paul Nielsen recently sat down with Matthew Butkovic, technical director of Risk and Resilience in the SEI's CERT Division, to discuss the evolution of software-defined warfare and the ways in which software engineering practices can meaningfully address the challenges of implementing software on the battlefield.

Transcript

Automatically generated from the audio. May contain errors.

We hear about DevOps and going faster and more incrementally in software development. That's part of software-defined warfare. We talk about model-based software. That's part of it.

Digital transformation is part of it. Worrying about data and controlling data and curating data, that's part of it too. Having good repositories of data is a really important thing too. And then actually having trained people and making sure you cherish those people.

So a lot of the things that at times look like they're a little disparate really come together under the overall goal of software-defined warfare. Earlier this year, the Pentagon's top cyber policy official said that integrating cyber effects into broader military operations represents the future of cyber warfare. The official noted that the goal is to enable more precise strikes, degrade an adversary's ability to command its forces, and support the U.S. military as it maneuvers on the battlefield.

Welcome to the SCI podcast series. My name is Matthew Bukovic. I'm the technical director of Cyber Risk and Resilience here in the CERT division of the Software Engineering Institute at Carnegie Mellon University.

I'm joined today by Dr. Paul Nielsen to discuss the evolution of software-defined warfare. But first, please let me give some background on our esteemed guest. During Dr. Nielsen's nearly 22-year tenure as the director and chief executive officer of the SCI, he helped bring modern software practices to the DOW

while enabling mission-critical cyber research to bolster national security. He also extended the SCI's impact and scope globally and recently saw the establishment of our artificial intelligence division in 2021. Prior to joining CMU, Dr. Nielsen served 32 years in the U.S. Air Force,

rising to the rank of Major General and Commander of the Air Force Research Lab. During his time at AFRL, he managed a 10,000-strong military and civilian team with an annual budget of approximately $3.5 billion. His career in research and development also included positions at various federal research organizations,

such as the National Security Agency, the National Reconnaissance Office, and Lawrence Livermore National Laboratory. It's my great honor to sit down with you today, Paul, and talk about the evolution of software-defined warfare. Sure, nice to be here with you, Matt.

So I think we should start with some definitions. The topic is software-defined warfare. I think we generally know what warfare is. We know what software is. Let's talk about the join between software and warfare. Yeah, I think that's an interesting point because it's a word, a term that's being bandied around quite a bit. It means different things to different people. For some people, it's a very narrow definition, such as software-defined radio, which was something about 35 years ago and maybe another device like that.

For others, it says it's really about the whole method, the whole strategy by which we wage war or prevent war. And I think the larger definition is the better one to think of. You know, recently, we'll probably talk about this some later, the Atlantic Council did a study about a year ago. And they kind of took the expansive definition of software-defined warfare to say it's not only about the devices, it's about the whole attitude and the fact that software is in the middle of almost everything now.

So you have to think of it that way. I think it's a great way to look at it, which is software is both adding great advantage, but it's also a through line through all these things as a potential source of risk. Yes. And it sounds like that's an evolution of thinking that's influencing both the way that we build in field systems, but also doctrine in the way that the U.S. military goes to war.

Yes, that's right. That's right. I think back to my early days in the Air Force when I was working on some spacecraft. And, you know, once you launch a spacecraft, especially in those days, you don't go up and fix it. But you could fix the software.

And so at some point we learned that having some software on the satellite allowed us to evolve capabilities on the spacecraft that we might not have been able to do otherwise. And that was a real good thing. So giving you sort of a newfound agility or flexibility with those systems. So when I think about some of those pressing issues in cyber and in defense, you know, artificial intelligence sort of rises to the surface.

So, Paul, what are your thoughts about using AI to speed analysis for things like targeting? Oh, gosh. And also, where does that fit in our description of software-defined warfare? Okay, that's a good point, too.

And, of course, first of all, you have to remember that while artificial intelligence techniques are a little bit more specific, basically they end up being software. They end up being data-driven, data-trained, data-controlled, and they sit inside systems that are largely software systems.

There may be a physical component of it, too, because we have a lot of cyber-physical systems. They start talking about self-driving cars, right? But ultimately, it's software that's involved in this.

So we at SEI always talk about the interplay between software, AI, and cyber. They each can help each other. They each open up new vulnerabilities that people have to consider as well. But you really have to think of them as a whole.

You have to look at them in all those respects. You don't want an AI system that's cyber vulnerable. You don't want an AI system that isn't written with good software, vice versa. So you want to be real careful about that.

It seems to me it's all about trustworthiness and sort of demonstrable reliability in some ways. Yeah, that's true. And I like to think that that's no different than how we think about people. Absolutely.

We do want trustworthy people. And the military and governments and companies all over go to a large extent to try to make sure they have trustworthy people.

This is the opening of the episode. Open the player for the full interactive transcript with clickable words, translation and flashcards.

Open full transcript

Audio belongs to its publisher and is played from their feed. Rights holders can request removal — copyright & takedown policy

Episodes · Software Engineering Institute (SEI) Podcast Series